Suspicious
Suspect

PE Executable
MD5: c2cf250459b71e67cb17349df6165e9f
Size: 715.26 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 c2cf250459b71e67cb17349df6165e9f
Sha1 79011302c59a57791c53da80fe41c685883a870a
Sha256 87c9b23d3ac3e48910f9d204708f95d337fab4161b5fc8a9a32735cfe7b8d83d
Sha384 6bcb840c204fcdb57be8874a93b5b7f871a543971f7d678bbf79c78a43cbca2ba080518fcadb86d4edccf753e8c4ebb6
Sha512 ebdd467132cfcdc8f0f1e24265ee752523b149121442e39ad61d78e99f372131c0b72525d22b050bb6d2a0f0050e01ca29d00b28f95798c9b7df299d2281e6d5
SSDeep 12288:m9xHC/KLQwtj2ry59AC5SrLjun4YvWg2IXg6tE+2Yel7EawMOt8:mDC/WZar62LgWSXg66ZYelg1i
TLSH A3E402631D98D743E4A063F62873CA782B693F4DA062E39F0BEA4CCFB5253194D89355
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DiceWars.HauptForm.resources
DiceWars.Properties.Resources.resources
NH
[NBF]root.Data
image_1832
[NBF]root.Data
[NBF]root.Data-preview.png
tIZLL
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: PwxeA.pdb
Module Name
PwxeA.exe
Full Name
PwxeA.exe
EntryPoint
System.Void DiceWars.Program::Main()
Scope Name
PwxeA.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
PwxeA
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
155
Main Method
System.Void DiceWars.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void DiceWars.HauptForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
PwxeA.exe
Full Name
PwxeA.exe
EntryPoint
System.Void DiceWars.Program::Main()
Scope Name
PwxeA.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
PwxeA
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
155
Main Method
System.Void DiceWars.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void DiceWars.HauptForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DiceWars.HauptForm.resources
DiceWars.Properties.Resources.resources
NH
[NBF]root.Data
image_1832
[NBF]root.Data
[NBF]root.Data-preview.png
tIZLL
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙